Privacy Policy
How Elec-Mate Ltd ("we", "us", "our") collects, uses, discloses and safeguards your personal data when you use the Elec-Mate platform, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller responsible for your personal data is:
Elec-Mate Ltd
Email:
info@elec-mate.com
ICO Registration Number: ZB935897 (verifiable at
ico.org.uk)
2. Personal Data We Collect
We collect data you provide directly to us, data generated through your use of the service, and limited data from third-party sources.
Account & identity data
- Full name, email address, optional phone number
- Username and password (securely hashed; we never store plaintext)
- Optional profile photograph and avatar
- Account role (apprentice, electrician, employer, college)
- Photos and images you capture or upload (site visit photos, board scanner images, portfolio evidence, document scans)
Professional & qualification data
- ECS card type, number and expiry
- Qualifications, certifications and training provider history
- Employer details and specialisations
- Elec-ID verification data
Learning & progress data
- Course enrolments, quiz scores, assessment results
- Study time, module progress, OJT entries, CPD hours logged
- Notes and bookmarks
Business & transaction data
- Customer records you create (names, addresses, contact details)
- Invoices and quotes generated
- Subscription and payment history
- Billing address and payment method (processed by Stripe / Apple / Google Play — we do not store full card details)
Technical & usage data
- IP address and approximate region
- Device type, operating system, browser version
- Pages visited, features used, session duration
- Precise GPS location only when you opt in for map-based features (e.g. job address lookup, travel time estimates)
- Crash reports and performance telemetry
3. How We Use Your Data
- Service delivery — providing the certificates, quotes, invoices, calculators, study modules and AI features that make up Elec-Mate.
- Elec-ID verification — confirming professional qualifications when you request it.
- Communication — sending transactional emails, push notifications and (with your consent) marketing.
- AI-powered features — passing your prompts and selected context to our AI models so they can answer regs questions, write quotes, generate RAMS, etc. We do not use your data to train third-party AI models.
- Platform improvement — anonymous aggregate analytics to find bugs and improve features.
- Legal & security — fraud prevention, security monitoring, complying with HMRC / Companies Act / VAT obligations.
4. Legal Basis for Processing
Under UK GDPR we rely on one or more of the following lawful bases:
- Contract — to deliver the service you've signed up for.
- Legitimate interests — for product analytics, security, fraud prevention.
- Consent — for marketing emails, optional analytics cookies, precise location.
- Legal obligation — for accounting records, tax filings, lawful disclosure to authorities.
5. Who We Share Your Data With
We do not sell your data. We share it only with vetted sub-processors who deliver the platform on our behalf:
- Supabase — database hosting, authentication, edge functions (EU/UK region)
- Vercel — web hosting and CDN
- Stripe — payment processing (subscriptions and invoices)
- RevenueCat — mobile in-app subscription management
- Apple App Store / Google Play — app distribution and mobile purchase processing
- Brevo / Resend — transactional email delivery
- OpenAI / Anthropic / Google — AI inference for the Elec-AI, Circuit Designer and Mate assistants. Prompts are not used to train these models.
- Sentry — error and performance monitoring
- Google Maps — geocoding and map rendering when you use map features
We may also disclose data when legally required to do so (court orders, regulatory requests) or to protect the rights, property or safety of Elec-Mate, our users or the public.
6. International Data Transfers
Some of our sub-processors are based outside the UK. Where data is transferred internationally we rely on UK Adequacy Regulations, the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs) with supplementary measures. We never transfer personal data to a country without an adequate level of protection.
7. Data Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Passwords stored using bcrypt with per-user salts
- Role-based access controls and row-level security on all user data
- 24/7 security monitoring and automated threat detection
- Regular dependency scanning and security patching
- Optional biometric / FaceID / fingerprint sign-in on supported devices
Despite these measures, no system is 100% secure. If a breach affects your data we will notify you and the ICO within 72 hours where required by law.
8. Data Retention
We keep personal data only as long as we need it.
| Data type | Retention period |
|---|---|
| Active account data | For the duration of your account |
| After account deletion request | Hard-purged within 30 days (see account deletion page) |
| Invoices, quotes converted to invoices, accounting records | 6 years (HMRC / Companies Act / VAT) |
| Issued certificates and qualifications | 7 years (BS 7671 record-keeping) |
| Support tickets and correspondence | 3 years after resolution |
| Security audit logs (sign-ins, deletions) | 12 months |
| Anonymised aggregate analytics | Indefinite (no PII) |
9. Your Rights Under UK GDPR
You have the following rights. To exercise any of them, email info@elec-mate.com or use the self-service tools in Settings → Privacy inside the app.
- Article 15 — Right of Access: Request a copy of the personal data we hold. Self-serve via Settings → Privacy → Download my data.
- Article 16 — Right to Rectification: Request correction of inaccurate data. Most fields editable in your profile.
- Article 17 — Right to Erasure (right to be forgotten): Request deletion. Self-serve via Settings → Privacy → Delete Account, or see our dedicated deletion page.
- Article 18 — Right to Restriction: Limit how we process your data while a dispute is resolved.
- Article 20 — Right to Data Portability: Receive your data in JSON format.
- Article 21 — Right to Object: Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Withdraw consent for optional processing at any time without affecting prior lawful processing.
- Article 22: We do not make any solely automated decisions with legal or significant effects on you.
We respond to valid requests within one month. In complex cases we may extend by two months and will let you know.
10. Cookies & Tracking
We use essential cookies to keep you signed in and remember your preferences, and optional analytics cookies to understand how the platform is used. You can manage your cookie preferences at any time inside the app under Settings → Privacy → Cookie preferences.
11. Children's Privacy
Elec-Mate is intended for professional use and people aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us at info@elec-mate.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology or legal requirements. We will notify you of material changes by email and/or a prominent in-app notice at least 30 days before they take effect.
13. Complaints
If you are unhappy with how we have handled your personal data you can lodge a complaint with the UK Information Commissioner's Office:
Information Commissioner's Office
Website: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
We'd appreciate the chance to address your concerns first — please get in touch before approaching the ICO.
14. Contact Us
Elec-Mate Ltd
Email:
info@elec-mate.com
Website: www.elec-mate.com
Account deletion: www.elec-mate.com/account-deletion
ICO Registration: ZB935897
We aim to respond within 5 working days.
This static page hosts the canonical privacy policy for both the Elec-Mate iOS and Android apps and the Elec-Mate website. It is served independently of the application so it can be reached without signing in and without JavaScript, in line with Google Play and App Store review requirements.